I've noticed in another Splunk environment at my site that they've set up what appear to be undocumented stanzas in props.conf
[foo:BAR]
REPORT-fooregex0=fooregex0
assume that foo is the sourcetype and BAR is a pattern in an event logged in the 'foo' sourcetype.
In the props.conf spec and example, and in numerous web searches I have failed to find a reference to this stanza type ...
Can someone give me some insight or point to some documentation on it?
Thanks very much.
Is that the exact spelling save for foo and BAR being changed? Then I'd guess the sourcetype actually is called foo:BAR.
This search might help you if you haven't seen it yet.
http://answers.splunk.com/answers/48072/relationship-between-propsconf-and-transformsconf